01Quiet by design
Modern attackers have learned that noise gets caught. Ransomware announces itself, but credential theft, inbox rules, and abused integrations do not. The average dwell time for a quiet compromise is still measured in weeks — long enough to map the network, find the data that matters, and plan the exit.
The common thread is legitimacy. Attackers use real accounts, real SaaS tools, and real permissions. To a log file, everything looks like normal work.
02The six threats
1. Stolen session tokens that skip passwords and MFA entirely.
2. Malicious inbox forwarding rules that quietly copy email outside the company.
3. Over-permissioned cloud apps and OAuth grants nobody remembers approving.
4. Dormant accounts — former employees and old vendors whose access still works.
5. Shadow IT tools where company data lives with no monitoring at all.
6. Supply-chain updates that arrive signed, trusted, and compromised.
03What actually helps
None of these are stopped by a single product. They are found by people who review access, question unusual-but-allowed behavior, and practice looking. That is a skill, and like every skill it is built through training — not purchased.
Start with visibility: know which accounts exist, which apps are connected, and what normal looks like. Then practice spotting the abnormal before it is real.
